← back
CVE-2019-25653

Navicat for Oracle 12.1.15 Password Field Denial of Service

CVSS 6.9 MEDIUMEPSS 0.2%CWE-620
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 0.2%KEV nãoPoC públicaPatch
Lifecycle
30 Mar 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characters into the password parameter during Oracle connection configuration to trigger an application crash.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →